{"component": "clause", "props": {"groups": [{"snippet": "a) Participating Agency will be notified of any changes to Supplier security policies applicable to Licensee Data with 90-days advance notice. If any changes are deemed unacceptable, Supplier will work with Participating Agency to arrive at mutually- acceptable security policy terms.\nb) Supplier promises to update the risk assessment and related safeguards at least annually. Upon request by the Participating Agency, Supplier agrees to provide documentation sufficient to demonstrate Supplier\u2019s security compliance for the Licensee Data.", "samples": [{"hash": "fGZFEDe1xi7", "uri": "/contracts/fGZFEDe1xi7#security-updates", "label": "Master Services Agreement", "score": 31.5672550201, "published": true}], "size": 3, "snippet_links": [{"key": "agency-will", "type": "clause", "offset": [17, 28]}, {"key": "changes-to", "type": "clause", "offset": [48, 58]}, {"key": "security-policies", "type": "clause", "offset": [68, 85]}, {"key": "licensee-data", "type": "definition", "offset": [100, 113]}, {"key": "advance-notice", "type": "clause", "offset": [127, 141]}, {"key": "will-work", "type": "clause", "offset": [192, 201]}, {"key": "policy-terms", "type": "definition", "offset": [271, 283]}, {"key": "risk-assessment", "type": "clause", "offset": [320, 335]}, {"key": "upon-request", "type": "clause", "offset": [378, 390]}, {"key": "the-participating", "type": "clause", "offset": [394, 411]}, {"key": "provide-documentation", "type": "clause", "offset": [439, 460]}, {"key": "security-compliance", "type": "clause", "offset": [498, 517]}, {"key": "for-the-licensee", "type": "definition", "offset": [518, 534]}], "hash": "13e445d1b8f05cbc601f98f78bc24cc2", "id": 8}, {"snippet": "Consultants receive all announcements from the relevant security lists of the underlying tools (Backdrop CMS, CiviCRM, Debian, Docker) that comprise the Software. Upon receipt of notification of available updates, Consultants will assess whether security updates are critical updates. Critical security updates will be tested within one business day of receipt of the notification. Non-critical security updates will be tested and implemented within 7 days of the receipt notification.", "samples": [{"hash": "4OPQBmlpqgo", "uri": "/contracts/4OPQBmlpqgo#security-updates", "label": "Work Agreement", "score": 29.1857452393, "published": true}, {"hash": "pXzua3QvhD", "uri": "/contracts/pXzua3QvhD#security-updates", "label": "Work Agreement", "score": 28.6792068481, "published": true}], "size": 3, "snippet_links": [{"key": "relevant-security", "type": "definition", "offset": [47, 64]}, {"key": "the-software", "type": "definition", "offset": [149, 161]}, {"key": "upon-receipt-of", "type": "definition", "offset": [163, 178]}, {"key": "notification-of", "type": "definition", "offset": [179, 194]}, {"key": "available-updates", "type": "clause", "offset": [195, 212]}, {"key": "day-of-receipt", "type": "definition", "offset": [346, 360]}], "hash": "994f1659787ec4c408e905fe0ad0b0d4", "id": 6}, {"snippet": "The engineering team maintains a listing of the \u201csunset dates\u201d of security support of all external software dependencies, and prioritizes updating those dependencies in advance of any sunsetting of security support. In addition, the engineering department maintains a weekly \u201csecurity rotation,\u201d supported by automated detection of dependency security updates (via Dependabot). This results in security updates typically being incorporated into the system within 1 week.", "samples": [{"hash": "2DpfOqx08MO", "uri": "/contracts/2DpfOqx08MO#security-updates", "label": "Student Data Privacy Agreement", "score": 35.5167694092, "published": true}, {"hash": "L3QgmKkTEJ", "uri": "/contracts/L3QgmKkTEJ#security-updates", "label": "Student Data Privacy Agreement", "score": 35.3355941772, "published": true}, {"hash": "4qKxfhOB9ZY", "uri": "/contracts/4qKxfhOB9ZY#security-updates", "label": "Supplemental Agreement", "score": 34.4559936523, "published": true}], "size": 8, "snippet_links": [{"key": "engineering-team", "type": "definition", "offset": [4, 20]}, {"key": "security-support", "type": "clause", "offset": [66, 82]}, {"key": "software-dependencies", "type": "definition", "offset": [99, 120]}, {"key": "in-advance", "type": "clause", "offset": [166, 176]}, {"key": "in-addition", "type": "clause", "offset": [216, 227]}, {"key": "engineering-department", "type": "definition", "offset": [233, 255]}, {"key": "the-system", "type": "definition", "offset": [445, 455]}], "hash": "c5eddfdabfd1342c6cc7e6971853c85f", "id": 1}, {"snippet": "Instabase may update the Security Measures from time to time, provided that any updates shall not materially diminish the overall security of Customer Personal Data. Notwithstanding anything to the contrary in the Agreement and this DPA, Customer agrees that it (not Instabase) shall be responsible for determining whether the Security Measures are appropriate for the processing of Customer Personal Data consistent with Customer's obligations under Applicable Data Protection Law.", "samples": [{"hash": "6uiq5WwxmTO", "uri": "/contracts/6uiq5WwxmTO#security-updates", "label": "Data Protection Agreement", "score": 35.1482315063, "published": true}, {"hash": "aIxT4LgNOC8", "uri": "/contracts/aIxT4LgNOC8#security-updates", "label": "Subscription Agreement", "score": 34.5992431641, "published": true}], "size": 2, "snippet_links": [{"key": "security-measures", "type": "clause", "offset": [25, 42]}, {"key": "from-time-to-time", "type": "clause", "offset": [43, 60]}, {"key": "provided-that", "type": "definition", "offset": [62, 75]}, {"key": "security-of", "type": "clause", "offset": [130, 141]}, {"key": "notwithstanding-anything-to-the-contrary", "type": "clause", "offset": [166, 206]}, {"key": "in-the-agreement", "type": "clause", "offset": [207, 223]}, {"key": "customer-agrees-that", "type": "clause", "offset": [238, 258]}, {"key": "responsible-for", "type": "clause", "offset": [287, 302]}, {"key": "processing-of-customer-personal-data", "type": "clause", "offset": [369, 405]}, {"key": "consistent-with", "type": "clause", "offset": [406, 421]}, {"key": "applicable-data-protection-law", "type": "definition", "offset": [451, 481]}], "hash": "7d89590b0b1224e213732ce7b5bbdfde", "id": 9}, {"snippet": "6.1. Licensee shall have a policy which requires that clients and servers of the Content Protection System are promptly and securely updated (as such updates become available) in the event of a security breach (that can be rectified using a remote update) being found in the Content Protection System and/or its implementations in clients and servers.\n6.2. Licensee shall have a policy to require that clients and servers of the Content Protection System are maintained and securely updated, to the extent commercially reasonable, with updates received from the provider of the Content Protection System.", "samples": [{"hash": "8mZw5AzBmJ3", "uri": "/contracts/8mZw5AzBmJ3#security-updates", "label": "Content Protection Requirements and Obligations", "score": 33.1995315552, "published": true}, {"hash": "hFy0VDnxlAb", "uri": "/contracts/hFy0VDnxlAb#security-updates", "label": "Content Protection Requirements and Obligations", "score": 30.8774375916, "published": true}], "size": 4, "snippet_links": [{"key": "licensee-shall", "type": "clause", "offset": [5, 19]}, {"key": "a-policy", "type": "clause", "offset": [25, 33]}, {"key": "content-protection-system", "type": "clause", "offset": [81, 106]}, {"key": "in-the-event-of-a", "type": "clause", "offset": [176, 193]}, {"key": "security-breach", "type": "clause", "offset": [194, 209]}, {"key": "to-the-extent", "type": "clause", "offset": [492, 505]}, {"key": "commercially-reasonable", "type": "definition", "offset": [506, 529]}, {"key": "the-provider", "type": "definition", "offset": [558, 570]}], "hash": "1f3a4af183f96a7d3d03a94a3300bd76", "id": 4}, {"snippet": "iManage uses commercially reasonable efforts to ensure that the Cloud Services operating systems and applications that are associated with Customer Data are patched and otherwise secured to mitigate the likelihood and impact of security vulnerabilities in accordance with iManage\u2019s patch management processes and within a reasonable time after iManage has actual or constructive knowledge of any critical or high-risk security vulnerabilities. iManage conducts vulnerability testing on a monthly basis.", "samples": [{"hash": "f77LGxiyV9", "uri": "/contracts/f77LGxiyV9#security-updates", "label": "Imanage Cloud Services Agreement", "score": 33.3701629639, "published": true}, {"hash": "6zfob8GAFpt", "uri": "/contracts/6zfob8GAFpt#security-updates", "label": "Imanage Cloud Services Agreement", "score": 26.8535251617, "published": true}, {"hash": "7k7DMD4BUMg", "uri": "/contracts/7k7DMD4BUMg#security-updates", "label": "Cloud Services Agreement", "score": 24.496919632, "published": true}], "size": 6, "snippet_links": [{"key": "commercially-reasonable-efforts", "type": "definition", "offset": [13, 44]}, {"key": "to-ensure", "type": "clause", "offset": [45, 54]}, {"key": "cloud-services", "type": "clause", "offset": [64, 78]}, {"key": "operating-systems", "type": "definition", "offset": [79, 96]}, {"key": "associated-with", "type": "definition", "offset": [123, 138]}, {"key": "customer-data", "type": "definition", "offset": [139, 152]}, {"key": "to-mitigate", "type": "definition", "offset": [187, 198]}, {"key": "security-vulnerabilities", "type": "clause", "offset": [228, 252]}, {"key": "in-accordance-with", "type": "clause", "offset": [253, 271]}, {"key": "management-processes", "type": "clause", "offset": [288, 308]}, {"key": "reasonable-time", "type": "definition", "offset": [322, 337]}, {"key": "knowledge-of", "type": "definition", "offset": [379, 391]}, {"key": "vulnerability-testing", "type": "clause", "offset": [461, 482]}, {"key": "monthly-basis", "type": "definition", "offset": [488, 501]}], "hash": "63c2fc0af3ad2a486b53ece5d242a939", "id": 2}, {"snippet": "To regularly update the security systems connected to the Personal Data and in accordance with the manufacturer's guidelines and recommendations. Critical updates (patches) should be applied no later than one week after they become aware to Au10tix. Encryption of Data in Public Networks. Not to permit access to the database infrastructure from the internet, and not to transmit the Personal Data over the internet or other public networks, except if the Personal Data is encrypted in an industry best-practice method of encryption and the user identifies him/herself through means that are under his/her exclusive control. Data Isolation. To logically isolate Personal Data to prevent isolation failures.", "samples": [{"hash": "Mht6dwi8kS", "uri": "/contracts/Mht6dwi8kS#security-updates", "label": "Data Protection Addendum", "score": 33.850339506, "published": true}, {"hash": "8EADTe3zWdA", "uri": "/contracts/8EADTe3zWdA#security-updates", "label": "Data Protection Addendum", "score": 27.5571517944, "published": true}, {"hash": "8ze7xjDBuzA", "uri": "/contracts/8ze7xjDBuzA#security-updates", "label": "Data Protection Addendum", "score": 26.9917869568, "published": true}], "size": 5, "snippet_links": [{"key": "security-systems", "type": "definition", "offset": [24, 40]}, {"key": "the-personal-data", "type": "definition", "offset": [54, 71]}, {"key": "in-accordance-with", "type": "clause", "offset": [76, 94]}, {"key": "the-manufacturer", "type": "definition", "offset": [95, 111]}, {"key": "one-week", "type": "definition", "offset": [205, 213]}, {"key": "encryption-of-data", "type": "clause", "offset": [250, 268]}, {"key": "public-networks", "type": "definition", "offset": [272, 287]}, {"key": "access-to-the-database", "type": "clause", "offset": [303, 325]}, {"key": "the-internet", "type": "clause", "offset": [346, 358]}, {"key": "to-transmit", "type": "definition", "offset": [368, 379]}, {"key": "industry-best", "type": "clause", "offset": [489, 502]}, {"key": "method-of", "type": "definition", "offset": [512, 521]}, {"key": "the-user", "type": "definition", "offset": [537, 545]}, {"key": "exclusive-control", "type": "definition", "offset": [606, 623]}], "hash": "09d028d5183a4d6dc4a86799f4dbef2b", "id": 3}, {"snippet": "CiteRight uses reasonable efforts to ensure that the CiteRight Services destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.", "samples": [{"hash": "aWYgFMFG6UE", "uri": "/contracts/aWYgFMFG6UE#security-updates", "label": "Software as a Service (Saas) Subscription Agreement", "score": 32.5516929626, "published": true}, {"hash": "grQybqcTPn8", "uri": "/contracts/grQybqcTPn8#security-updates", "label": "Software as a Service (Saas) Subscription Agreement", "score": 31.8043899536, "published": true}, {"hash": "eSsqeRPudoZ", "uri": "/contracts/eSsqeRPudoZ#security-updates", "label": "Software as a Service (Saas) Subscription Agreement", "score": 31.5388660431, "published": true}], "size": 3, "snippet_links": [{"key": "reasonable-efforts", "type": "definition", "offset": [15, 33]}, {"key": "to-ensure", "type": "clause", "offset": [34, 43]}, {"key": "citeright-services", "type": "definition", "offset": [53, 71]}, {"key": "disclosure-of", "type": "clause", "offset": [116, 129]}, {"key": "access-to-customer-data", "type": "clause", "offset": [134, 157]}], "hash": "ab593761ed3e1756164e11b3247ddaf0", "id": 5}, {"snippet": "After registering for this service, free concise security updates will be e-mailed daily to the Insured Person\u2019s inbox for the reminder of the Period of Insurance.", "samples": [{"hash": "kZNICvQLuWd", "uri": "/contracts/kZNICvQLuWd#security-updates", "label": "Personal Accident & Travel Insurance", "score": 19.9568786621, "published": true}, {"hash": "kHn5h5zOmxj", "uri": "/contracts/kHn5h5zOmxj#security-updates", "label": "Personal Accident & Travel Insurance", "score": 19.9568786621, "published": true}], "size": 3, "snippet_links": [{"key": "the-insured-person", "type": "definition", "offset": [92, 110]}, {"key": "period-of-insurance", "type": "clause", "offset": [143, 162]}], "hash": "5087227800a4656fcde5770a1f347e6d", "id": 7}, {"snippet": "CiteRight uses reasonable efforts to ensure that the CiteRight Services operating systems and applications that are associated with Customer Data are patched and otherwise secured to mitigate the likelihood and impact of security vulnerabilities in accordance with CiteRight patch management processes and within a reasonable time after CiteRight has actual or constructive knowledge of any critical or high-risk security vulnerabilities.", "samples": [{"hash": "eoDCBaXZfer", "uri": "/contracts/eoDCBaXZfer#security-updates", "label": "Software as a Service (Saas) Subscription Agreement", "score": 33.7150726318, "published": true}, {"hash": "aIwvCpKWsEw", "uri": "/contracts/aIwvCpKWsEw#security-updates", "label": "Software as a Service (Saas) Subscription Agreement", "score": 32.9677696228, "published": true}], "size": 2, "snippet_links": [{"key": "reasonable-efforts", "type": "definition", "offset": [15, 33]}, {"key": "to-ensure", "type": "clause", "offset": [34, 43]}, {"key": "citeright-services", "type": "definition", "offset": [53, 71]}, {"key": "operating-systems", "type": "definition", "offset": [72, 89]}, {"key": "associated-with", "type": "definition", "offset": [116, 131]}, {"key": "customer-data", "type": "definition", "offset": [132, 145]}, {"key": "to-mitigate", "type": "definition", "offset": [180, 191]}, {"key": "security-vulnerabilities", "type": "clause", "offset": [221, 245]}, {"key": "in-accordance-with", "type": "clause", "offset": [246, 264]}, {"key": "management-processes", "type": "clause", "offset": [281, 301]}, {"key": "reasonable-time", "type": "definition", "offset": [315, 330]}, {"key": "knowledge-of", "type": "definition", "offset": [374, 386]}], "hash": "b8780f02798575786e752887d29fa909", "id": 10}], "next_curs": "ClkSU2oVc35sYXdpbnNpZGVyY29udHJhY3RzcjULEhZDbGF1c2VTbmlwcGV0R3JvdXBfdjU2IhlzZWN1cml0eS11cGRhdGVzIzAwMDAwMDBhDKIBAmVuGAAgAA==", "clause": {"children": [["", ""], ["costs-and-expenses", "Costs and expenses"], ["preferred-law-firm", "Preferred law firm"], ["das-standard-terms-of-appointment", "DAS Standard Terms of Appointment"], ["bail-bond", "Bail Bond"]], "title": "Security Updates", "size": 48, "parents": [["network-and-host-security", "Network and Host Security"], ["information-security-infrastructure", "Information Security Infrastructure"], ["professional-services", "Professional Services"], ["professional-services-data-ownership", "Professional Services Data; Ownership"], ["scheduled-downtime", "Scheduled Downtime"]], "id": "security-updates", "related": [["security-technology", "Security Technology", "Security Technology"], ["software-updates", "Software Updates", "Software Updates"], ["security-audit", "Security Audit", "Security Audit"], ["security-cameras", "Security Cameras", "Security Cameras"], ["security-audits", "Security Audits", "Security Audits"]], "related_snippets": [], "updated": "2025-07-17T06:21:00+00:00", "also_ask": ["What minimum update frequency and scope should be mandated to ensure robust security?", "How can parties allocate liability for delayed or inadequate security updates?", "What are the best practices for defining 'security update' to avoid ambiguity?", "How do courts interpret obligations for security updates in the absence of explicit standards?", "How does this clause compare to industry norms and regulatory requirements for security updates?"], "drafting_tip": "Specify update frequency and responsibilities to ensure timely protection; define notification procedures to keep parties informed; require compliance with industry standards to maintain security integrity.", "explanation": "The Security Updates clause requires parties to regularly update and maintain the security features of their systems or software to protect against vulnerabilities. This typically involves installing patches, updating antivirus definitions, and promptly addressing newly discovered security threats. By mandating ongoing security maintenance, the clause helps prevent data breaches and ensures that systems remain resilient against evolving cyber risks."}, "json": true, "cursor": ""}}